← IdenTrust Services, LLC cases
Bugzilla #1991215 Certificate Misissuance

IdenTrust: ICA with invalid CDP

RESOLVED FIXED IdenTrust Services, LLC
AI Summary

IdenTrust issued a subordinate CA certificate on September 15, 2025, which contained an invalid Certificate Revocation List (CRL) Distribution Point (CDP). The error was identified the following day, leading to the certificate's revocation on September 17, 2025. The mis-issuance was due to an incorrect value being copied into the certificate profile, which went undetected due to a lack of enforcement in the approval workflow. No end-entity certificates were issued from this CA, thus no relying parties were affected. IdenTrust has since implemented a systematic enforcement mechanism to ensure all certificate profiles undergo proper review before issuance.

Model: gpt-4o-mini Generated: 2026-06-13 21:32 UTC Confidence: 0.90
Chronology
  1. Issued production Subordinate CA
  2. Identified issue with production Subordinate CA
  3. Revoked the misissued Subordinate CA
  4. Report closure summary provided
Participants
IdenTrust
External References
Related Bugzilla IDs Mentioned
Similar Local Cases
#1446121 RESOLVED Certificate Misissuance Opened 2018-03-15 · Closed 2023-02-22 · 59% similar
IdenTrust: Improper encoding of wildcard certificate
#2014610 RESOLVED Certificate Misissuance Opened 2026-02-05 · Closed 2026-04-11 · 58% similar
IdenTrust: Root OCSP Signer certificate mis-issuance
#1910195 RESOLVED Certificate Misissuance Opened 2024-07-26 · Closed 2024-09-06 · 58% similar
IdenTrust: Invalid special characters in S/MIME Certificates
#1744627 RESOLVED Certificate Misissuance Opened 2021-12-06 · Closed 2023-02-22 · 58% similar
IdenTrust: Issuance of OV SSL Certificate with doc vetting older than 398 days
#1753287 RESOLVED Certificate Misissuance Opened 2022-02-02 · Closed 2024-07-08 · 58% similar
IdenTrust: Validation Source for EV Certificates not Publicly Disclosed
#2006483 RESOLVED Certificate Misissuance Opened 2025-12-16 · Closed 2026-01-20 · 57% similar
IdenTrust: CT Logging Mistakes
#1851710 RESOLVED Certificate Misissuance Opened 2023-09-05 · Closed 2024-01-04 · 57% similar
IdenTrust: Delay beyond 5 days in revoking misissued certificates
#1930029 RESOLVED Certificate Misissuance Opened 2024-11-08 · Closed 2025-02-19 · 57% similar
IdenTrust: Approval of TLS certificate renewal without domain validation

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action